Description
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent.
Published: 2026-07-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cap’s GET /api/video/ai endpoint does not verify the requester’s ownership or group membership before returning private AI‑generated metadata such as titles, summaries, and chapters. As a result, any authenticated user can supply an arbitrary video identifier, read confidential AI, and trigger additional AI‑generation operations that consume the video owner’s credits.

Affected Systems

The affected vendor is Cap:Cap. The product is the Cap platform’s Video AI service. No specific product or version numbers were supplied, so all current releases of Cap are potentially affected until a fix is applied.

Risk and Exploitability

The vulnerability scores a CVSS of high severity. The likely attack vector is an authenticated network fact that the endpoint requires valid credentials, making it a network‑based, authenticated score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation at present. Nevertheless, the combination of confidentiality loss and resource consumption creates a significant risk for impacted organizations.

Generated by OpenCVE AI on July 26, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy any vendor‑issued update that implements ownership endpoint, addressing the CWE‑862 access‑control flaw.
  • If a patch is not yet available, enforce access controls that limit this endpoint to the video owner or authorized roles, preventing arbitrary ID queries.
  • Monitor API traffic for repeated or suspicious requests to /api/video/ai and block or alert on anomalous activity.

Generated by OpenCVE AI on July 26, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent.
Title Cap - Missing Access Control in Video AI Metadata Endpoint
First Time appeared Capnproto
Capnproto capnproto
Weaknesses CWE-862
CPEs cpe:2.3:a:capnproto:capnproto:*:*:*:*:*:*:*:*
Vendors & Products Capnproto
Capnproto capnproto
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Capnproto Capnproto
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-20T17:45:58.593Z

Reserved: 2026-07-06T15:31:46.187Z

Link: CVE-2026-59704

cve-icon Vulnrichment

Updated: 2026-07-08T13:01:58.942Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:00:02Z

Weaknesses